CVE-2025-24440

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
Updated: Apr 1, 2025
CWE ID 787

Summary

CVE-2025-24440 is a newly identified vulnerability affecting Substance3D's Sampler software versions 4.5.2 and earlier. This issue involves an out-of-bounds write vulnerability, which means that data is being written beyond the intended memory bounds. An attacker can exploit this flaw to write arbitrary code, potentially leading to code execution in the context of the current user. However, it's important to note that for an exploit to be successful, user interaction is required as users must open a maliciously crafted file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share